Blacknevas

Active
BlackNevas is a ransomware group first observed in November 2024, believed to be derived from the Trigona ransomware family, targeting telecommunications, manufacturing, medical, and legal industries primarily in Asia-Pacific, the UK, Italy, and Lithuania using double-extortion with a dual AES/RSA encryption scheme.
46 Victims
Apr 24, 2023 First Discovered
Aug 25, 2026 Last Discovered
22 Days Inactive
0% Infostealer
1/1 Sites Online
Known Locations (1)
DLS
ctyfftrjgtwdjzlgqh4avbd35sqrs6tde4oyam2ufbjch6oqpqtkdtid.onion
Victims (46)

Detailed victim list temporarily unavailable

This group has 46 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.